Application Security Lead
Application Security Lead

Application Security Lead

Full-Time 80000 - 100000 £ / year (est.) Home office possible
Prolific

At a Glance

  • Tasks: Lead application security strategy and ensure robust protection of sensitive data.
  • Company: Prolific, a pioneer in human data infrastructure for AI development.
  • Benefits: Competitive salary, remote work, and a mission-driven culture.
  • Other info: Opportunity for career growth and mentoring within a dynamic team.
  • Why this job: Join us at the forefront of AI innovation and make a real impact.
  • Qualifications: Experience in software engineering and application security is essential.

The predicted salary is between 80000 - 100000 £ per year.

Prolific is not just another player in the AI space – we are the architects of the human data infrastructure that's reshaping the landscape of AI development. In a world where foundational AI technologies are increasingly commoditized, it's the quality and diversity of human-generated data that truly differentiates products and models.

Security at Prolific isn't an afterthought, it's foundational to how we build. As a company trusted by world-leading research institutions and AI labs to handle sensitive data at scale, the security of our platform and the code that powers it is critical. We handle participant data, researcher credentials, payment flows, and API integrations, and we need someone to own how we protect all of it at the application layer.

As Application Security Lead, you'll own Prolific's application security strategy and be the most senior security engineering voice in the organisation. You'll define and drive our Secure Software Development Lifecycle (SSDLC), set the standard for how security is embedded into engineering, and get hands-on with code review, threat modelling, and security testing when it matters. You'll also manage our Senior Application Security Engineer and continue to own our compliance programme alongside these responsibilities. This is a player-coach role. You won't just set strategy, you'll be in the code, leading by example, and building the security culture that scales with Prolific. You'll need deep engineering experience to earn the trust of our engineering teams, and deep application security experience to know where the real risks are. You'll report to the Head of Engineering/Platform and work cross-functionally with product engineering, platform, data, TechOps, and legal teams. As we scale, there's a clear path for this role to grow into leading a broader security function.

What you’ll bring to the role:

  • Several years of experience in software engineering, you’ve built and shipped production systems at scale
  • Several years in application security (testing, code review, threat modelling, vuln management)
  • Expert knowledge of OWASP Top 10 (Web & API) and modern attack paths (e.g. auth flaws, SSRF, injection, business logic, supply chain)
  • Strong understanding of modern architectures (microservices, APIs, event-driven systems)
  • Python for security tooling and automation (Django a strong plus)
  • Hands-on testing experience (e.g. Burp Suite) and manual assessment of apps/APIs
  • Experience building and scaling SSDLCs, including CI/CD tooling (SAST, SCA, DAST, secrets)
  • Experience leading threat modelling and security design reviews
  • Strong engineering partnership skills, you influence through trust
  • Experience with ISO 27001 / SOC 2 and translating controls into real engineering practices
  • Clear communicator across technical and non-technical audiences

Nice to haves:

  • Experience mentoring or managing security engineers
  • Experience with Django, Vue.js, MongoDB, GCP
  • Security champions or bug bounty programmes
  • Supply chain or infrastructure security (e.g. Terraform, Kubernetes)
  • Hands-on certifications (OSCP, GWAPT, BSCP, CISSP)
  • Experience building AppSec in a scaling company

What you’ll be doing in the role:

You’ll own and evolve Prolific’s application security strategy end-to-end, from hands-on testing and threat modelling to scaling secure development practices across engineering. You’ll act as the go-to expert for application security, partnering with engineering leadership to balance risk and velocity, while building the tooling, processes, and culture needed to embed security into how we ship. This includes mentoring an AppSec engineer, leading high-impact security reviews, owning vulnerability management, and ensuring our platform stays ahead of modern threats.

Why Prolific is a great place to work:

We've built a unique platform that connects researchers and companies with a global pool of participants, enabling the collection of high-quality, ethically sourced human behavioral data and feedback. This data is the cornerstone of developing more accurate, nuanced, and aligned AI systems. We believe that the next leap in AI capabilities won't come solely from scaling existing models, but from integrating diverse human perspectives and behaviors into AI development. By providing this crucial human data infrastructure, Prolific is positioning itself at the forefront of the next wave of AI innovation – one that reflects the breadth and the best of humanity. Working for us will place you at the forefront of AI innovation, providing access to our unique human data platform and opportunities for groundbreaking research. Join us to enjoy a competitive salary, benefits, and remote working within our impactful, mission-driven culture.

Application Security Lead employer: Prolific

Prolific is an exceptional employer that places a strong emphasis on security as a foundational element of its innovative AI platform. With a mission-driven culture, competitive salary, and remote working options, employees are empowered to grow their careers while contributing to groundbreaking research in human data infrastructure. Joining Prolific means being at the forefront of AI innovation, with ample opportunities for professional development and a supportive environment that values diverse perspectives.
Prolific

Contact Detail:

Prolific Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Application Security Lead

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repo showcasing your projects, especially those related to application security. This gives potential employers a taste of what you can do and sets you apart from the crowd.

✨Tip Number 3

Prepare for interviews by brushing up on common application security scenarios and challenges. Practice explaining your thought process and how you approach problem-solving – it’s all about showing your expertise and confidence!

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are genuinely interested in joining our mission at Prolific.

We think you need these skills to ace Application Security Lead

Application Security
Secure Software Development Lifecycle (SSDLC)
Code Review
Threat Modelling
Vulnerability Management
OWASP Top 10
Microservices Architecture
APIs
Python
Burp Suite
Continuous Integration/Continuous Deployment (CI/CD)
Security Design Reviews
ISO 27001
Communication Skills
Mentoring

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in application security and software engineering. We want to see how your skills align with our needs, so don’t hold back on showcasing your relevant projects!

Show Off Your Technical Skills: When you’re detailing your experience, be specific about the tools and technologies you've used, especially around OWASP Top 10 and secure coding practices. We love seeing hands-on experience, so mention any testing or threat modelling you've done!

Communicate Clearly: Remember, we need someone who can bridge the gap between technical and non-technical teams. Use clear language in your application to demonstrate your ability to communicate complex ideas simply. This will help us see how you can fit into our culture.

Apply Through Our Website: We encourage you to submit your application directly through our website. It’s the best way for us to keep track of your application and ensure it gets the attention it deserves. Plus, it shows you’re keen to join our team!

How to prepare for a job interview at Prolific

✨Know Your Stuff

Make sure you brush up on your application security knowledge, especially the OWASP Top 10 and modern attack paths. Be ready to discuss how you've applied this knowledge in real-world scenarios, as they'll want to see your hands-on experience.

✨Showcase Your Engineering Skills

Since this role requires deep engineering experience, be prepared to talk about the production systems you've built and shipped. Highlight your familiarity with modern architectures like microservices and APIs, and don’t shy away from discussing your coding skills, particularly in Python.

✨Demonstrate Leadership and Mentorship

As a player-coach, you'll need to show that you can lead by example. Share examples of how you've mentored others or led security reviews. They’ll be looking for someone who can build a security culture, so highlight any past experiences where you've influenced teams positively.

✨Communicate Clearly

You’ll be working with both technical and non-technical teams, so practice explaining complex security concepts in simple terms. Prepare to discuss how you've balanced risk and velocity in previous roles, as effective communication will be key to your success in this position.

Application Security Lead
Prolific

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>